Desk Pilot

Legal

HIPAA & Security Statement


Effective 1 September 2026 · Last updated 1 September 2026

Desk Pilot answers calls, follows up with patients and books appointments for healthcare practices. That means we handle protected health information, and we do it as a HIPAA Business Associate under a signed agreement with every practice we serve.

Are you a patient? This page is written for practices evaluating Desk Pilot. If you want to know how your own health information is used, or you want to see or correct your records, contact the practice that treats you. They hold your records and are the right first call. We will support any request they pass to us.

1. Our role: Business Associate

Under HIPAA, the practice is the covered entity and Desk Pilot is a Business Associate. We create, receive, maintain and transmit protected health information solely to perform the services the practice has engaged us for, and only as the Business Associate Agreement and HIPAA permit.

We do not use protected health information for our own purposes. We do not use it for our own marketing, we do not sell it, and we do not share it with anyone outside the chain of service the practice has authorised.

2. Business Associate Agreements

We sign a Business Associate Agreement with every practice before we handle any protected health information. It is a precondition of service, not an optional extra, and it is executed as part of onboarding.

Our BAA covers permitted uses and disclosures, our safeguard obligations, subcontractor flow-down, breach notification timelines, your access and amendment rights, and what happens to your data when the relationship ends. If your compliance team prefers to paper the arrangement on your own form, we will review it.

To request a copy for review, email sales@deskpilot360.com.

3. What information we handle

We work on the minimum necessary principle — we ask for and use only what the task requires. In practice that usually means:

  • Patient name and contact details, including phone number and email address
  • Appointment dates, times, type and status
  • The reason for a call or enquiry, at the level of detail the patient volunteers
  • Insurance or payer information where scheduling requires it
  • Call recordings and message logs, where the practice has enabled them

We do not need, and do not ask for, clinical records, diagnoses or treatment notes beyond what a patient volunteers when booking.

4. Safeguards

Administrative

  • Written policies and procedures covering privacy, security and breach response
  • HIPAA training for every member of the workforce before they handle protected health information, and refresher training thereafter
  • Confidentiality agreements signed by all staff
  • Role-based access, so staff can reach only the information their role requires
  • A designated point of contact for privacy and security matters
  • Prompt revocation of access when someone leaves or changes role

Technical

  • Encryption of protected health information in transit and at rest
  • Unique user accounts with multi-factor authentication
  • Audit logging of access to systems holding protected health information
  • Session timeouts and automatic logoff
  • Vendor platforms selected on the basis that they will sign a Business Associate Agreement

Physical and operational

  • Workstation and device controls for staff handling protected health information
  • A US-based team, with no offshore outsourcing of patient contact
  • Secure disposal of information no longer required

5. Subcontractors and vendors

Where a subcontractor or platform handles protected health information on our behalf — for example telephony, messaging or scheduling infrastructure — we put a Business Associate Agreement in place with them that imposes obligations at least as protective as those in our agreement with you. We can provide a current list of these vendors on request during your due diligence.

6. Text messaging and patient contact

Appointment reminders and follow-up are treated as healthcare operations. We send them at the practice’s direction and only to patients the practice tells us have given prior express consent, and we keep the content limited to what scheduling requires. Patients can stop messages at any time by replying STOP; opt-outs are honoured immediately and recorded.

Mobile numbers and SMS consent records are never sold, shared, rented, released or traded with third parties or affiliates for marketing or promotional purposes. Our SMS Terms set out the detail.

7. Breach notification

If we discover a breach of unsecured protected health information, we will notify the affected practice without unreasonable delay and within the timeframe set by the Business Associate Agreement and the HIPAA Breach Notification Rule. Our notice will cover what happened, what information was involved, what we are doing about it, and what we recommend. We will cooperate fully with the practice’s own notification obligations.

8. When the relationship ends

On termination we return or securely destroy the protected health information we hold, as the Business Associate Agreement directs. Where return or destruction is not feasible, we extend the protections of the agreement to the retained information and limit further use to the purposes that make return or destruction infeasible.

9. What this page is and is not

This page describes the safeguards we apply and the commitments we make. It is not a Notice of Privacy Practices — that is the practice’s document to issue to its patients. It is not legal advice, and it does not replace the Business Associate Agreement, which is the binding document between us. HIPAA does not offer a government certification for Business Associates; any vendor claiming to be “HIPAA certified” is describing a third-party assessment, not an official status.

Talk to us about compliance

Due diligence questions, security questionnaires and BAA requests are welcome — they are a normal part of onboarding.

Desk Pilot LLC
1379 E Canyon Creek Dr
Gilbert, AZ 85295
Email: sales@deskpilot360.com
Phone: 623-294-9505

Scroll to Top